Skip to content

Latest commit

 

History

History
43 lines (36 loc) · 1.58 KB

c4caf910-d72e-47b6-9315-d17636c04ca2.md

File metadata and controls

43 lines (36 loc) · 1.58 KB

Mappings: CloudTrail - s3.amazonaws.com - GetBucketAcl

Input Requirements

Input Value
Vendor AWS
Product CloudTrail
Log Format JSON
Event ID Regex Pattern AwsApiCall-GetBucketAcl

Record Output

Output Value
Vendor Amazon AWS
Product CloudTrail
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
accountId userIdentity.accountId
action eventName
application eventSource
changeTarget requestParameters.bucketName
changeType None The static text get is populated in this schema field.
cloud_provider None The static text AWS is populated in this schema field.
cloud_region awsRegion
cloud_service None The static text S3 is populated in this schema field.
description None The static text A request was made to access the access control list of an S3 bucket is populated in this schema field.
device_ip sourceIPAddress
http_userAgent userAgent
normalizedAction None The static text access is populated in this schema field.
normalizedResource None The static text bucket is populated in this schema field.
normalizedSeverity None The static text 1 is populated in this schema field.
resource requestParameters.bucketName
resourceType None The static text bucket is populated in this schema field.
srcDevice_ip sourceIPAddress
timestamp eventTime We expect the orginal record value of eventTime is in the format yyyy-MM-dd'T'HH:mm:ss'Z'
user_username userIdentity.sessionContext.sourceIdentity